arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Agentic-ZTA:一种用于自主零信任实施的多智能体架构

Agentic-ZTA: A Multi-Agent Architecture for Autonomous Zero Trust Enforcement

Shovan Roy, Lopamudra Praharaj, Maanak Gupta, Bhavani Thuraisingham

arXiv 2610.05782首次发表:更新:

发表机构

Tennessee Tech University; University of North Carolina Pembroke; The University of Texas at Dallas(田纳西理工大学; 北卡罗来纳大学彭布罗克分校; 德克萨斯大学达拉斯分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出Agentic-ZTA多智能体架构,通过检索增强生成和策略引擎智能体实现NIST零信任控制循环,在测试平台上达到95.0%准确率、93.9%精确率和96.3%召回率,验证了AI智能体实施零信任的可行性。

AI 中文摘要

Agentic AI正成为一种自动化复杂网络安全决策的有前景范式,然而其在实施零信任中的应用在安全性、可靠性和策略合规性方面带来了重大挑战。本文提出了一种基于Agentic AI的零信任架构(Agentic-ZTA),该架构通过协调的多智能体决策流水线,实现了NIST SP 800-207 ZTA架构控制循环的运作。在所提出的框架中,策略知识被嵌入到检索增强生成流水线中,并在推理时作为top-k相关策略被检索。访问请求由策略执行点(PEP)拦截,并附加上下文元数据。请求上下文被路由到策略引擎智能体,该智能体首先调用领域专用的核心智能体,若需进一步评估,则随后调用支持智能体。AI智能体对访问上下文和策略约束进行推理,并确定信任度。检索到的策略在推理时被嵌入到智能体提示中,智能体信任分数由信任算法聚合和评估,从而在持续验证下产生最终的访问决策以供实施。我们在一个测试平台上实现了Agentic-ZTA,并在代表性的访问控制用例场景中对其进行了评估。我们的Agentic-ZTA框架达到了95.0%的准确率、93.9%的精确率和96.3%的召回率,证明了使用AI智能体实施零信任的可行性。

英文摘要

Agentic AI is emerging as a promising paradigm for automating complex cybersecurity decisions, yet its use in enforcing zero trust introduces significant challenges in safety, reliability, and policy compliance. This paper presents Agentic AI based zero trust architecture (Agentic-ZTA) that operationalizes the NIST SP 800-207 ZTA architecture control loop through coordinated multi- agent decision pipeline. In the proposed framework, policy knowledge is embedded into a retrieval-augmented generation pipeline and retrieved at inference time as top-k relevant policies. Access requests are intercepted by the Policy Enforcement Point (PEP), enriched with contextual metadata. The request context is routed to a policy engine agent which invokes domain-specialized core agents first followed by supporting agents, if further evaluation needed. AI agents reason over access context, policy constraints and determine trust. The retrieved policies are embedded into agent prompt during inference time and agentic trust scores are aggregated and evaluated by a trust-algorithm, producing the final access decision for enforcement under continuous verification. We implement Agentic-ZTA in a testbed and evaluate it on representative access-control use cases scenarios. Our Agentic-ZTA framework achieves 95.0% accuracy, 93.9% precision, and 96.3% recall, and demonstrate the feasibility of enforcing zero trust using AI agents.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑